Last updated: August 28, 20261. Scope & parties
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Media Yard LLC (New Jersey, USA — “we”, the processor) and you, the professional using ClientLoft (the controller). It applies whenever your use of the Service involves personal data of your own clients — the details you enter about them and, above all, the documents and answers they submit through their portals. No separate signature is required: this DPA is automatically effective for all business customers.
2. What we process, and for whom
- Data subjects: your clients — the people and businesses you collect documents from.
- Categories of data: the client names and email addresses you enter; the checklist items you create; and the files and typed answers your clients submit — which may include sensitive material such as financial statements, tax documents, and identity records.
- Nature and purpose: hosting each client’s private portal, storing what they submit, delivering it to you for review and download, and sending the reminder and status emails you trigger. Nothing else.
- Duration: for as long as you keep the client in your account, plus the deletion window in section 7.
3. Our commitments as processor
- We process your clients’ personal data only on your documented instructions — which, for ClientLoft, means only as needed to provide the Service as described in the Terms. We never open, analyze, or use uploaded documents for any purpose of our own — no advertising, profiling, resale, or AI training (see the AI disclosure).
- Everyone with access to production data (currently, only the operator of the Service) is bound to confidentiality.
- We apply the security measures in section 5 and will not weaken them during your subscription.
- We will assist you, to the extent reasonably possible, in responding to data-subject requests (access, correction, deletion, export) and in meeting your own security, confidentiality, and impact-assessment obligations — including professional obligations that apply to accountants and similar practitioners.
- If we become aware of a personal-data breach affecting your clients’ data, we will notify you without undue delay at your account email, with the information we have about its nature and scope.
4. Subprocessors
You authorize the subprocessors we use to run the Service:
- Netlify — application hosting and delivery (US)
- Neon — database hosting, including uploaded files (Postgres, US region, encrypted at rest)
- Resend — transactional email delivery (US); reminder emails carry the portal link, never the documents themselves
- Stripe — billing (processes your payment data as its own controller, not your clients’ data)
No AI provider is a subprocessor — client data is never sent to one. If we add or replace a subprocessor that will process your clients’ personal data, we will update this page and notify account holders by email at least 14 days in advance, and you may object on reasonable data-protection grounds (and terminate if we can’t resolve the objection).
5. Security measures
- Encryption in transit (TLS) for all connections, and encryption at rest by our database provider — uploaded files included.
- Each portal is reachable only by its own long, unguessable link; portals set no cookies and expose no client-to-client visibility.
- Documents can be opened or downloaded only by the authenticated owner of the client they belong to — there are no public file URLs.
- Passwordless authentication with single-use, expiring sign-in links — no password database to breach.
- Production access limited to the operator of the Service; infrastructure credentials stored in the hosting providers’ secret managers, not in code.
6. International transfers
All processing takes place in the United States. If you are subject to EU/UK data-transfer rules, the protections in this DPA and our subprocessors’ own compliance frameworks apply to those transfers; contact us if your compliance program requires additional documentation.
7. Deletion & return
Deleting a client in your dashboard permanently deletes their uploaded files immediately. When your account closes, we delete your clients’ personal data within 30 days, except minimal records we are legally required to keep. Before closure — or within 30 days after — you can request an export of your clients’ submissions at legal@getclientloft.com.
8. Audits & information
We will make available the information reasonably necessary to demonstrate compliance with this DPA. Written requests to legal@getclientloft.com are answered within 30 days; this page, the Privacy Policy, and the AI disclosure together describe our processing in full.
9. Precedence & contact
If this DPA conflicts with the Terms on a data-protection matter, this DPA controls. Questions: Media Yard LLC · legal@getclientloft.com.